EMAIL-017: Spoofing and Authentication Protection

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Critical
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Spoofing and authentication protections guard against domain spoofing, employee name spoofing, and unauthenticated email from domains that appear similar to the organization

Recommended value

All spoofing and authentication protections enabled with quarantine action

Remediation

Admin Console > Apps > Google Workspace > Gmail > Safety > Spoofing and authentication > Enable all protections: domain spoofing, employee name spoofing, inbound email spoofing, and unauthenticated email

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-017
ScenarioExpected verdict
no-dataNot Assessed

Framework mappings

NIST SP 800-53
SI-8, IA-9
CIS Benchmark
2.17
CISA SCuBA
GWS.GMAIL.7.1v1, GWS.GMAIL.7.2v1, GWS.GMAIL.7.3v1, GWS.GMAIL.7.4v1, GWS.GMAIL.7.5v1, GWS.GMAIL.7.7v1
MITRE ATT&CK
T1566.001, T1566.002, T1036.005